PDF Blocks
PricingSupport
Start Free
Go to Page

Data Processing Addendum

The Data Processing Addendum governing how Modern Paper, Inc. processes personal data on behalf of PDF Blocks customers, including EU Standard Contractual Clauses and CCPA terms.

Last updated 9 July 2026

1. Introduction and Incorporation

This Data Processing Addendum (“DPA”) forms part of the Terms & Conditions or other written agreement between you (“Customer”) and Modern Paper, Inc. (“Modern Paper”, “we”, “us”, or “our”) governing your use of PDF Blocks (the “Agreement”). It reflects the parties’ agreement on the processing of Personal Data in connection with the Service.

This DPA is provided at no charge and does not depend on any third-party platform. It applies automatically and is incorporated into the Agreement when Customer uses the Service to process Personal Data that is subject to Data Protection Laws. No signature is required for this DPA to be effective; by accepting the Agreement or using the Service, you agree to this DPA. If you require a countersigned copy, contact privacy@pdfblocks.com.

In the event of a conflict between this DPA and the rest of the Agreement in relation to the processing of Personal Data, this DPA prevails. In the event of a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses prevail.

2. Definitions

  • “Data Protection Laws” means all laws applicable to the processing of Personal Data under the Agreement, including, where applicable, the GDPR, the UK GDPR, the Swiss FADP, and the CCPA.
  • “GDPR” means Regulation (EU) 2016/679. “UK GDPR” means the GDPR as incorporated into United Kingdom law. “Swiss FADP” means the Swiss Federal Act on Data Protection.
  • “CCPA” means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act (CPRA), and its regulations.
  • “Customer Personal Data” means Personal Data contained in the documents, files, and data that Customer submits to the API for processing and that Modern Paper processes solely on Customer’s behalf under the Agreement. It does not include the account, billing, or website data that Modern Paper processes as a Controller for its own purposes, which is addressed in the Privacy Policy and is outside the scope of this DPA.
  • “Controller”, “Processor”, “Data Subject”, “Personal Data”, “processing”, and “Supervisory Authority” have the meanings given in the GDPR. “Business”, “Service Provider”, “Personal Information”, “Sell”, and “Share” have the meanings given in the CCPA.
  • “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
  • “Standard Contractual Clauses” or “SCCs” means the clauses in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, available at eur-lex.europa.eu.
  • “Subprocessor” means any Processor engaged by Modern Paper to process Customer Personal Data.

3. Roles of the Parties

This DPA governs only Modern Paper’s processing of Customer Personal Data as a Processor on Customer’s behalf. In respect of that processing, Customer is the Controller (or a Processor acting on behalf of a third-party Controller) and Modern Paper is the Processor (or Subprocessor).

Modern Paper’s separate processing of account, billing, and website data as a Controller for its own purposes is outside the scope of this DPA and is described in our Privacy Policy. Each party will comply with its obligations under Data Protection Laws.

4. Scope and Instructions for Processing

Modern Paper will process Customer Personal Data only on documented instructions from Customer, including as set out in the Agreement, this DPA, and Customer’s configuration and use of the Service, and as required to provide the Service and comply with applicable law. If Modern Paper is required by law to process Customer Personal Data beyond these instructions, it will inform Customer of that requirement before processing, unless the law prohibits such notice on important grounds of public interest.

Modern Paper will notify Customer if, in its opinion, an instruction infringes Data Protection Laws. The subject matter, duration, nature, and purpose of the processing, and the types of Personal Data and categories of Data Subjects, are described in Annex I.

Customer submits documents to, and receives results from, Modern Paper solely through the API. Modern Paper does not receive or transmit Customer documents by email or any other channel. Documents submitted to the API are processed transiently, in memory, to perform the requested operation and are not retained after the response is returned, as further described in our Privacy Policy.

5. Customer Obligations

Customer is responsible for the accuracy and lawfulness of Customer Personal Data and for having an appropriate legal basis to submit it to the Service and to authorise its processing under this DPA. Customer will provide any notices and obtain any consents required from Data Subjects. Customer will not submit special categories of Personal Data, or data subject to heightened regulatory regimes (such as protected health information under HIPAA), except as permitted by the Agreement’s Acceptable Use section or as separately agreed in writing.

6. Confidentiality

Modern Paper will ensure that persons authorised to process Customer Personal Data are bound by an appropriate obligation of confidentiality and process that data only as instructed.

7. Security Measures

Modern Paper will implement and maintain appropriate technical and organisational measures to protect Customer Personal Data against a Personal Data Breach, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. Those measures are described in Annex II and may be updated from time to time provided the level of protection is not materially reduced.

8. Personal Data Breaches

Modern Paper will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to it to help Customer meet its own breach obligations. Modern Paper will take reasonable steps to mitigate and remedy the breach.

9. Subprocessors

Customer provides general authorisation for Modern Paper to engage Subprocessors to process Customer Personal Data. The current Subprocessors are listed in Annex III. Modern Paper will impose data-protection obligations on each Subprocessor that are no less protective than those in this DPA and remains responsible for its Subprocessors’ performance.

Modern Paper will give Customer at least 30 days’ notice before adding or replacing a Subprocessor, by updating Annex III and, where Customer has subscribed to notifications, by email. Customer may object on reasonable data-protection grounds within that period; the parties will work in good faith to resolve the objection, and if they cannot, Customer may terminate the affected part of the Service.

10. Data Subject Requests

Taking into account the nature of the processing, Modern Paper will assist Customer, by appropriate technical and organisational measures and insofar as possible, to respond to requests from Data Subjects to exercise their rights. If Modern Paper receives a request directly from a Data Subject relating to Customer Personal Data, it will not respond except on Customer’s instructions or as required by law, and will promptly forward the request to Customer.

11. Assistance to the Customer

Taking into account the nature of the processing and the information available to it, Modern Paper will assist Customer in ensuring compliance with its obligations regarding security, breach notification, data protection impact assessments, and prior consultation with a Supervisory Authority.

12. Deletion and Return of Personal Data

Documents submitted to the API are not retained after processing. Because Modern Paper does not retain Customer Personal Data in its role as Processor, no separate deletion or return step is required on termination. Modern Paper’s handling of the account and usage data that it processes as a Controller is governed by the Privacy Policy and is outside the scope of this DPA.

13. Audits and Records

Modern Paper will make available to Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor it mandates. The parties agree that audits will ordinarily be satisfied by Modern Paper providing relevant documentation, security summaries, and responses to reasonable questionnaires. On-site audits will be limited to once per year (absent a Personal Data Breach or Supervisory Authority requirement), on reasonable prior notice, during business hours, and subject to confidentiality.

14. International Data Transfers

Where Modern Paper processes Customer Personal Data that is transferred out of the European Economic Area (EEA), the United Kingdom, or Switzerland to a country that does not ensure an adequate level of protection, the following transfer mechanisms apply.

14.1 EU Standard Contractual Clauses

The SCCs are incorporated into this DPA by reference and completed as follows:

  • Module Two (Controller to Processor) applies where Customer is a Controller; Module Three (Processor to Processor) applies where Customer is itself a Processor acting for a third-party Controller.
  • Clause 7 (Docking clause) applies.
  • Clause 9(a): Option 2 (general written authorisation) applies, with the minimum notice period stated in Section 9 of this DPA.
  • Clause 11(a): the optional independent dispute-resolution option does not apply.
  • Clause 17 (Governing law): Option 1 applies, and the SCCs are governed by the law of Ireland.
  • Clause 18(b) (Choice of forum): the courts of Ireland.
  • Annexes I, II, and III of the SCCs are populated by Annexes I, II, and III of this DPA. The data exporter is Customer; the data importer is Modern Paper.

14.2 United Kingdom

For transfers subject to the UK GDPR, the SCCs as incorporated above are supplemented by the International Data Transfer Addendum issued by the UK Information Commissioner (“UK Addendum”), which is incorporated by reference. Table 1 is completed with the parties’ details in Annex I.A; Tables 2 and 3 with the SCCs and Annexes as incorporated above; and for Table 4, neither party may end the UK Addendum when the approved Addendum changes, save as set out in its terms. The UK Addendum’s Mandatory Clauses apply.

14.3 Switzerland

For transfers subject to the Swiss FADP, the SCCs apply with these amendments: references to the GDPR are to the FADP; the competent authority is the Swiss Federal Data Protection and Information Commissioner; the SCCs also protect the Personal Data of legal entities until the FADP no longer requires it; and Swiss Data Subjects may enforce their rights in Switzerland.

14.4 Alternative Transfer Mechanism

If Modern Paper adopts an alternative lawful transfer mechanism, that mechanism applies to the relevant transfers instead of the SCCs to the extent it is superseded.

15. California Consumer Privacy Act

Where Modern Paper processes Personal Information of California residents on Customer’s behalf, Modern Paper acts as a Service Provider and the terms in Annex IV apply.

16. Liability

Each party’s liability arising out of or related to this DPA and the SCCs, whether in contract, tort, or under any other theory of liability, is subject to the limitations and exclusions of liability set out in the Agreement.

17. Term

This DPA takes effect on the earlier of Customer’s acceptance of the Agreement or first use of the Service to process Personal Data, and remains in effect until the Agreement terminates and Modern Paper has ceased processing Customer Personal Data.

Annex I — Description of Processing

A. List of Parties

Data exporter: the Customer identified in the Agreement, acting as Controller (or Processor) of Customer Personal Data. Contact: the account owner’s contact details in the Customer’s account.

Data importer: Modern Paper, Inc., a Delaware corporation, acting as Processor. Contact: privacy@pdfblocks.com.

B. Description of the Transfer

  • Categories of Data Subjects: determined by Customer; typically Customer’s employees, contractors, customers, and other individuals whose Personal Data appears in the documents or data Customer submits to the API.
  • Categories of Personal Data: determined by Customer; any Personal Data contained in the documents and data Customer submits to the API. Customer controls what it submits.
  • Special categories of data: not intended to be processed; Customer must not submit special-category or regulated data except as separately agreed (see Section 5).
  • Frequency of the transfer: continuous, on Customer’s use of the Service.
  • Nature and purpose of processing: performing PDF processing operations (such as merging, splitting, password protection, watermarking, stamping, and page manipulation) on the documents Customer submits through the API.
  • Duration: document content is processed transiently and is not retained after the response is returned.
  • Subprocessors: as listed in Annex III, processing for the duration of their engagement.

C. Competent Supervisory Authority

Where Customer is established in an EEA member state, the Supervisory Authority of that member state. Where Customer is not established in the EEA but has appointed a representative under Article 27 GDPR, the Supervisory Authority of the representative’s member state. In all other cases, the Irish Data Protection Commission acts as the competent Supervisory Authority for the SCCs.

Annex II — Technical and Organisational Measures

Modern Paper maintains, at a minimum, the following measures:

  • Encryption: TLS for data in transit on every API call; AES encryption applied to password-protected document output.
  • Ephemeral processing: submitted documents are processed in memory and are not written to durable storage; any temporary buffering required for a single request is deleted when the request completes.
  • Pseudonymisation of credentials: account passwords are stored only as salted hashes, and API keys are stored only as one-way digests; document contents are not logged.
  • Access control: role-based, least-privilege access to production systems, with multi-factor authentication for administrative access.
  • Network security: segmented cloud networks, firewalls, a web application firewall, and TLS-terminating load balancers.
  • Physical security: hosting in cloud data centres that maintain recognised security certifications (see Annex III).
  • Logging and monitoring: security-event logging and request-metadata monitoring, configured to avoid capturing document content.
  • Resilience: auto-scaling and multi-availability-zone deployment across the hosting providers listed in Annex III.
  • Vulnerability management: a secure development lifecycle, dependency management, and remediation of identified vulnerabilities.
  • Personnel: confidentiality obligations and security awareness for staff with access to Customer Personal Data.
  • Incident response: a documented process for detecting, responding to, and notifying Personal Data Breaches.

Annex III — List of Subprocessors

Modern Paper engages the following Subprocessors to host and operate the Service and to carry out the transient processing of documents Customer submits through the API. These are the only Subprocessors that process Customer Personal Data:

  • Amazon Web Services, Inc. — cloud hosting and compute. Locations: the regions in which the Service operates — United States, European Union, United Kingdom, Canada, Australia, Japan, India, and Brazil.
  • Microsoft Corporation (Microsoft Azure) — cloud hosting and compute. Locations: the regions in which the Service operates — United States, European Union, United Kingdom, Canada, Australia, Japan, India, and Brazil.

Modern Paper will give notice of any addition or change to this list as provided in Section 9.

Annex IV — California Consumer Privacy Act (Service Provider Terms)

These terms apply to the extent Modern Paper processes Personal Information of California residents on Customer’s behalf. Customer is the Business and Modern Paper is a Service Provider. Modern Paper will:

  • process Personal Information only to perform the Service and for the business purposes specified in the Agreement and this DPA, and not for any other purpose;
  • not Sell or Share Personal Information;
  • not retain, use, or disclose Personal Information outside the direct business relationship with Customer, or for any commercial purpose other than the specified services, except as permitted by the CCPA;
  • not combine Personal Information received under the Agreement with personal information from other sources, except as permitted by the CCPA;
  • provide the same level of privacy protection as required of a Business under the CCPA, and comply with its applicable obligations;
  • assist Customer in responding to verifiable consumer requests to know, access, correct, delete, and opt out; and
  • notify Customer if it determines that it can no longer meet its obligations under the CCPA.

Modern Paper certifies that it understands and will comply with these restrictions. Neither party will attempt to reidentify any deidentified data it receives.

Contact

Questions about this DPA, or requests for a countersigned copy, may be sent to privacy@pdfblocks.com.